Every supervised financial institution outsources something. Core banking platforms, cloud infrastructure, transaction monitoring, parts of compliance, sometimes an entire back office. Swiss supervisory law allows this, on one condition that never changes: the institution remains responsible. FINMA supervises you, not your provider.
The requirements themselves are well known — an inventory of outsourced functions, a materiality assessment, contracts that secure oversight, audit and access rights, managed sub-outsourcing. The real difficulty lies elsewhere. In most institutions, three versions of the outsourcing landscape exist side by side: the register, the contracts, and what actually happens in operations. They start out aligned. They rarely stay that way.
Three versions of the truth
The register says what the institution believes it has outsourced. The contracts say what was agreed, often years ago. Operations show what the provider actually does today — which, after a few change requests, a migration and a product launch, can be something else entirely.
Drift is not negligence; it is the default. A provider adds a module, and suddenly it processes client-identifying data it never touched before. An internal team shrinks, and a "support" arrangement quietly becomes the function itself. None of these steps feels like an outsourcing decision. Together, they change what the register should say and what the contract should govern.
The test a supervisor or audit firm applies is simple: pick one outsourced function and follow it through register, contract and reality. If the three tell different stories, the finding writes itself.
Materiality is a judgment — record it
Not every purchased service is an outsourcing, and not every outsourcing carries the same weight. The heavier obligations attach to functions that are material to the institution — essential to its business, its risk management or its compliance. That assessment is a judgment call, and you should expect to defend it.
Two practices make it defensible. First, assess materiality against your institution, not in the abstract: a service that is peripheral for a large bank may be existential for a fintech with twelve employees. Second, write the reasoning down at the time of the decision, and revisit it when the service changes. A one-line "not material" from four years ago protects nobody.
Audit and access rights that actually work
Every outsourcing contract with a regulated institution contains audit and access clauses; templates have seen to that. The question is whether they work. Rights that exist on paper but cannot be exercised — because the provider sits abroad, because the clause covers the provider but not the data centre it relies on, because "audit" turns out to mean receiving a summary of someone else's report — are findings waiting to happen.
Read these clauses operationally. Who may show up, where, on what notice, to see what? Do the rights extend to your regulator and your audit firm, not only to you? Could you actually retrieve your data, in usable form, if the relationship ended badly? If the honest answer to any of these is "we would have to negotiate at the time", the clause has not done its job.
The chain below the contract
Sub-outsourcing is where visibility usually ends. Your provider outsources to a specialist, the specialist runs on a hyperscaler, and a support function sits in a third country. Your responsibility does not stop at the first link — but your contract often does.
The workable approach is not to prohibit sub-outsourcing, which providers will not accept, but to structure it: approval or at least notification for material sub-providers, flow-down of the audit and data-protection commitments you depend on, and a current picture of where your functions and data actually sit. If you cannot name the countries involved, you cannot assess the risk.
Keeping the map current
Institutions that handle this well treat outsourcing as a lifecycle, not a filing exercise. Every new service and every significant change passes through the same gate: is this an outsourcing, is it material, what must the contract secure? The register updates because the process feeds it, not because someone remembers. Contracts are re-read when services change, not when the audit letter arrives.
Whether a given arrangement is material, and what its contract must contain, always depends on the facts of your institution. But the discipline of comparing what registers say, what contracts secure and what operations show is universal — and it is exactly the kind of structured reading that systems do well, with a lawyer deciding what the gaps mean and which to fix first. If you suspect your three versions of the truth have drifted apart, we are happy to help you find out.